Opens an external site
- Employment type
- Full-time
- Experience level
- Senior · 5+ years
- Minimum education
- Professional degree
- Posting language
- English
- Working hours
- 40 hours per week
Job summary
Lead security risk assessments for cloud environments, third-party vendors, and AI/ML-enabled products to ensure the confidentiality and integrity of information assets. Collaborate with global technical teams to embed security throughout the software development lifecycle and maintain high-quality risk documentation.
Job details
The Information Technology (IT) team plays a key role in providing business enablement throughout ResMed. We are focused on application, infrastructure, and user productivity solutions, with innovation, efficiency and security. Our goal is providing customer oriented agile delivery, effective business partnership and state-of-the-art technology solutions. This global role within Resmed’s Enterprise Security Group is responsible for ensuring the confidentiality, integrity, and availability of Resmed’s information assets and computing infrastructure. We are seeking a seasoned and proactive Information Security Specialist to lead security risk assessments across cloud environments, third-party vendor solutions, and AI/ML-enabled products. The successful candidate will demonstrate strong technical expertise, risk analysis capabilities, and communication skills to engage independently with project teams, advise on secure design principles, and deliver high-quality reports that inform business decisions and support audit readiness. This position requires close collaboration with enterprise security leadership, business stakeholders, and technical teams across diverse time zones and cultures to ensure alignment between security strategy and organizational objective. Let’s talk about Responsibilities Lead security engagement across global projects, ensuring alignment of security practices with business and technical goals. Conduct end-to-end security risk assessments for cloud-native and hybrid deployments, including architecture and control reviews for new implementations and managed services. Evaluate third-party products during onboarding and integration to ensure security and compliance requirements are met. Lead security reviews of AI/ML-based products, focusing on secure product design, guardrail enforcement, and risk mitigation. Collaborate with project managers, product owners, architects, and developers to embed security throughout the SDLC. Communicate security risks and mitigation strategies in business-relevant language. Produce and maintain high-quality documentation, including risk assessments, security summaries, and remediation recommendations. Track risks and controls using GRC tools, ensuring traceability and accountability. Stay current with emerging technologies, threats, and best practices in information security. Contribute to continuous improvement of internal security frameworks and processes. Let’s talk about Qualifications and Experience Required: Proven ability to independently lead security risk assessment across diverse technologies. Exposure in third-party security risk management process and platforms. Strong understanding of key security areas including: Authentication, Authorization, Encryption, Application and Network security, DLP, Endpoint protection, CSPM, CASB, PAM, ZTNA, Logging, Monitoring, Vulnerability Management, and Incident response. Preferred: Bachelor’s degree. Minimum of 5 years of related experience. Professional certifications such as CISSP, CISM, CCSP, CRISC, or AWS Security Specialty. Familiarity with regulatory and industry compliance framework, including ISO27001, SOC 2, GDPR, HIPAA, AI Risk Frameworks (NIST AI RMF, ISO/IEC 42001) Exposure and knowledge of AWS cloud security controls. Experience in healthcare or manufacturing environment is an advantage. Joining us is more than saying “yes” to making the world a healthier place. It’s discovering a career that’s challenging, supportive and inspiring. Where a culture driven by excellence helps you not only meet your goals, but also create new ones. We focus on creating a diverse and inclusive culture, encouraging individual expression in the workplace and thrive on the innovative ideas this generates. If this sounds like the workplace for you, apply now! We commit to respond to every applicant.
What you’ll do
Lead security risk assessments for cloud environments, third-party vendors, and AI/ML-enabled products to ensure the confidentiality and integrity of information assets. Collaborate with global technical teams to embed security throughout the software development lifecycle and maintain high-quality risk documentation.
Requirements
Requires a minimum of 5 years of experience in information security with strong technical expertise in cloud security and risk analysis. Preferred qualifications include a bachelor's degree and professional certifications such as CISSP, CISM, or CCSP.
Listed skills
- Software · Preferred
- Technical · Preferred
- assessment · Preferred
- analysis · Preferred
- Collaboration · Preferred
- Teams · Preferred
- Compliance · Preferred
- management · Preferred
- Development · Preferred
- Agile · Preferred
- Amazon Web Services · Preferred
- Audit · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Security Risk Assessment
- Cloud Security
- Third-Party Risk Management
- AI/ML Security
- Secure SDLC
- GRC Tools
- Network Security
- Identity and Access Management
- Vulnerability Management
- Incident Response
- AWS Security
- Compliance Frameworks
- Cloud-Native Computing
- Healthcare Industry Knowledge
- Security Risk Management
- Certified Cloud Security Professional (CCSP)
- Accountability
- General Data Protection Regulation (GDPR)
- AWS Certified Security Specialty
- Endpoint Security
- Business Decisions
- Technology Solutions
- Emerging Technologies
- Risk Mitigation
- Cloud Access Security Broker Tools (CASBs)
- Security Risk
- Artificial Intelligence Risk
- Agile Methodology
- Artificial Intelligence
- Amazon Web Services
- Auditing
- Authentications
- Certified Information Systems Security Professional
- Certified Information Security Manager
- Communication
- Information Technology
- Confidentiality
- Continuous Improvement Process
- Certified In Risk And Information Systems Control
- Encryption
- Design Elements And Principles
- Enterprise Security
- Governance Risk Management And Compliance
- Leadership
- Health Insurance Portability And Accountability Act (HIPAA) Compliance
- Innovation
- ISO/IEC 27001
- Machine Learning
- Managed Services
- Project Management
Job areas
- Security & Safety
- Technology
- Software
- Healthcare
- Manufacturing
- IT Information Security Specialist
- Cyber Security Specialist / Technician
- Database and Network Professionals Not Elsewhere Classified
- Information Security Analysts
More jobs from Resmed
Software Engineer
- Hybrid
- Halifax, NS
- Posted Sep 24, 2026
Sr. Global Product Marketing Manager, Consumer Digital
- Remote
- Posted Sep 23, 2026
Senior Database Developer - MongoDB
- On-site
- NS
- Posted Sep 3, 2026
Senior AI Engineer, Platform Engineering
- On-site
- Halifax, NS
- Posted Jun 24, 2026
